1. understanding the problem, requirements and objectives
2. designing the solution and getting approval/deployment
3. integrate all applications and environments
General Context & Main Objective Strategic Vision: The client aims to evolve its operating model toward a "Pentest-as-a-Service" approach.
Current Challenge: Internal teams face recurring difficulties during the onboarding phase. The process suffers from a lack of clarity regarding integration, obtaining necessary access for all web applications, and upfront preparation.
Mission Objective: The mandate focuses on structuring, process implementation, and operational optimization rather than a purely technical or execution-based role.
2. Role and Expected Responsibilities
- The successful candidate’s primary mission will be to act as a coordinator and designer of offensive security processes:
Defining processes and procedures: Designing and drafting procedures for the onboarding, preparation, and organization of penetration tests. Coordinating application onboarding: Establishing explicit mechanisms for managing access and technical prerequisites for the applications to be tested.
Proposing improvements and tooling
- Proposing methodological improvements.
- Automating/scripting interfaces and connections between various security tools where necessary.
- Implementing or recommending solutions (including tracking databases) to streamline workflows.
- Understanding application standards: Assessing and integrating web application security and certification requirements into the overall process.
3. Desired Profile and Skills
- Large enterprise experience: The candidate must come from or have worked in large, structured environments (preferred sectors: banking, finance, insurance).
- Key competency (Process vs. Pure Pentesting): Concrete experience in designing upstream processes and drafting procedures is required. Profiles of "pure pentester" consultants—who handle only the technical execution phase without involvement in structuring or preparation—are not suitable.
- Technical understanding of Red Teaming/Pentesting: A solid technical foundation in penetration testing and web application security is required to fully grasp access and certification requirements.
Langues parlées et écrites / Languages spoken and written: English Niveau d'expérience / Level of experience: Senior
Années d'expérience / Years of experience: 10
Exigences minimum / Minimum requirements:
1. IT solution delivery experience
2. In depth understanding of web application and API authentication mechnisms
3. Experience in designing processes and writing procedures
Technologies demandées / Technologies required: Autres exigences / Other requirements: